OverviewJob Purpose
The Director, Security Compliance is responsible for overseeing Pattern's IT security compliance program, including NERC CIP Reliability Standards, Sarbanes-Oxley (SOX) IT General Controls in support of Pattern's IPO readiness, and the enterprise Governance, Risk and Compliance (GRC) framework across Pattern's IT and OT environments.
This role serves as the technical Subject Matter Expert bridging compliance requirements and Pattern's IT/OT architecture, partnering with Security Operations, IT Operations, Legal, Internal Audit, and Pattern's separate Regulatory Compliance department to ensure comprehensive coverage. The position reports to the CTO on an interim basis, pending the hire of a Chief Information Security Officer who will consolidate Security and Compliance.
Key Accountabilities
- Oversee Pattern's NERC CIP compliance program (Operations & Planning and Critical Infrastructure Protection Standards) across IT and OT environments; serve as Subject Matter Expert cross-functionally and ensure audit readiness.
- Own the SOX IT General Controls program ahead of Pattern's IPO via a dedicated SOX Lead; ensure testing, documentation, and remediation are completed on schedule.
- Own Pattern's enterprise Governance, Risk and Compliance (GRC) framework and tooling administration via a dedicated GRC Lead, including chairing the Risk Review Board.
- Manage direct reports (Senior Manager, NERC Compliance; SOX Lead; GRC Lead) and coordinate with Security Operations and IT Operations to maintain the compliance oversight/evaluate/execute boundary.
- Lead all NERC-related engagements, including audits, spot checks, self-certifications, ad hoc data requests, and NERC Alerts.
- Develop, revise, and maintain IT/OT security policies, standards, and governance documentation as part of the internal governance framework.
- Monitor industry and regulatory compliance trends (NERC, SOX/SEC, evolving cybersecurity regulation) and communicate impacts to leadership and impacted stakeholders.
- Verify new and updated IT and OT assets are correctly classified and documented for NERC CIP compliance as part of the asset integration workflow.
Experience/Qualifications/Education Required
- Bachelor's degree in Information Security, Computer Science, or a related field (or equivalent experience).
- At least 10 years of combined experience in IT/OT security and regulatory compliance (NERC CIP, SOX/ITGC, GRC), including direct technical exposure.
- Proven ability to translate regulatory and compliance requirements into technical controls across IT and OT environments.
- Strong knowledge of internal control, compliance, and procedure development, with the ability to manage risk for a scalable program.
- Effective communication skills, with the ability to translate technical items efficiently for internal stakeholders.
- Results-oriented and comfortable managing multiple concurrent priorities.
- CISSP or equivalent certification.
- Experience in critical infrastructure or energy-sector compliance.
- Prior experience in a scaling or IPO-track organization.
- Established working relationships with NERC and regional entity auditors.
The expected starting pay range for this role is $145,000.00 - $200,000.00 USD. This range is an estimate and base pay may be above or below the ranges based on several factors including but not limited to location, work experience, certifications, and education. In addition to base pay, Pattern’s compensation program includes a bonus structure for full-time employees of all levels. We also provide a comprehensive benefits package which includes medical, dental, vision, short and long-term disability, life insurance, voluntary benefits, family care benefits, employee assistance program, paid time off and bonding leave, paid holidays, 401(k)/RRSP retirement savings plan with employer contribution, and employee referral bonuses.
#LI-AT1 #LI-Hybrid